No Data displayed Spunk LOGbinder

No Data displayed Spunk LOGbinder

I have setup Splunk with SuperCharger to monitor AD changes but no data is being displayed on the dashboard. In the event log AD Changes i can see the forwarded events being recorded here. An initial check of domiancontrollers.csv showed the file was empty and i added the list of domain controllers manually but no data is being displayed on the dashboard and when i search in Splunk

I have setup Splunk with SuperCharger to monitor AD changes but no data is being displayed on the dashboard. In the event log AD Changes i can see the forwarded events being recorded here. An initial check of domiancontrollers.csv showed the file was empty and i added the list of domain controllers manually but no data is being displayed on the dashboard and when i search in Splunk

Where is SuperCharger sending those events? Did you create an input for that in Splunk?

I have setup Splunk with SuperCharger to monitor AD changes but no data is being displayed on the dashboard. In the event log AD Changes i can see the forwarded events being recorded here. An initial check of domiancontrollers.csv showed the file was empty and i added the list of domain controllers manually but no data is being displayed on the dashboard and when i search in Splunk

Where is SuperCharger sending those events? Did you create an input for that in Splunk?

SuperCharger is sending those events to the Splunk server. There is an input created in Splunk to collect those logs

I have setup Splunk with SuperCharger to monitor AD changes but no data is being displayed on the dashboard. In the event log AD Changes i can see the forwarded events being recorded here. An initial check of domiancontrollers.csv showed the file was empty and i added the list of domain controllers manually but no data is being displayed on the dashboard and when i search in Splunk

Where is SuperCharger sending those events? Did you create an input for that in Splunk?

SuperCharger is sending those events to the Splunk server. There is an input created in Splunk to collect those logs

By default the app is monitoring exactly the same directory[WinEventLog://Supercharger-Destination-ADChanges/Log]

If nothing was changed in the inputs.conf then by default it is sending data to index=main

As the next step please check if index=main is populated with data from that source.